NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43693  CVE-2012-1826  dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.    Medium  2017-01-19  2012-11-26  View
45485  CVE-2012-4007  The mixi application before 4.3.0 for Android allows remote attackers to read potentially sensitive information in friends" comments via a crafted application that leverages the storage of these comments on an SD card.    4.3  Medium  2017-01-19  2012-08-20  View
45741  CVE-2012-4325  Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts.    6.8  Medium  2017-01-19  2012-08-15  View
46253  CVE-2012-5004  Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the authentication of admins for requests that (1) add group plans via admin/group_plans.html or (2) add extra packages via admin/extra_packs/create_extra_pack.html.    6.8  Medium  2017-01-19  2012-09-21  View
46765  CVE-2012-5665  ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.    4.3  Medium  2017-01-19  2013-01-03  View

Page 14757 of 17672, showing 5 records out of 88360 total, starting on record 73781, ending on 73785

Actions